Food Delivery
The full itemised basket travels to the merchant and the courier, and your order history feeds the ad market through named networks and brokers. How long it stays is the company's own judgement, and a dispute extends even that.
The read at a glance
Every order pins your home address to a time of day.
A leak exposes your home address, your card, and your habits.
Order and address history is kept for years; courier checks longer.
Ordering needs payment and address; couriers pass identity and right-to-work checks.
Industry profile reviewed 23 August 2026. Also machine-readable via the free API.
If it leaks
Your home address sits attached to your name, your phone number and the hours you are usually in. Breaches here have spilled that exact set for millions of customers at once.
What repeats in the policies
The basket carries more than food
Your name, your delivery address and the full itemised basket go to the merchant and the courier. The list is not only food: a prescription or an allergy can ride inside it, and an age-restricted order can put your ID under a scan at the door.
Your order history feeds the ad market
What you ate, when and where is used to target ads. Several policies name the ad networks and data brokers that receive your order-linked identifiers, and the same brokers recur across rival apps. Some also buy data about you from brokers to fill out the profile your orders started. In the US, several policies call this flow a sale or a share and leave the opt-out to you.
How long it stays is their claim
Most policies name no number: they keep your record as long as they judge necessary, and a complaint or an expected dispute extends even that. Where a policy does set a ceiling it runs long: fifteen years in one, seven in another. Asking to close the account is what starts anything moving, and one policy allows itself around ninety days to finish the deletion.
What a company here typically holds
Worked out from the industry, not from any one company. What you actually handed over is yours to record.
What this can reveal about you
Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.
Where you go Likely
Delivery addresses map where you are and when.
Health Possible
Dietary and pharmacy orders can imply conditions.
What lawfully stays after you leave
Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.
Employment and payroll records Law sets it about 6 years
Payroll, right-to-work, and pension records carry statutory retention.
Fraud-prevention markers They set it about 2 to 6 years
To flag suspected fraud, often on a shared industry database you cannot reach through the company.
Tax and accounting records Law sets it about 6 years
Tax and company law makes them keep billing and payment records.
Records tied to a live or potential dispute They set it the limitation period of the claim
They can keep records to defend a live or possible legal claim.
Who wants this data
Your home address tied to your order history is one record the ad market buys. One platform traded its customers' names, addresses and order histories into a marketing cooperative, and a US state regulator called that a sale.
Sold or shared Likely
Order and location data has a resale and partnership market.
AI training Moderate
Ordering patterns train demand and routing models.
Even anonymised, this can still be you
Delivery addresses and times are mobility data, where four time-and-place points single out 95% of people (de Montjoye et al., 2013).
Name, date of birth, postcode Typical
Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).
Location traces Typical
Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).
Payment patterns Typical
Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).
Face and voice Typical
A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.
Browsing fingerprint Typical
Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).
The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)
The wording that does the work
Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
“if you have turned on location access, we may store your precise location, including while our apps run in the background”
With location turned on, the app can take your device's precise position for the span of the order, and in this wording even while it sits in the background of your phone. Your delivery address becomes a live read rather than a stored field until the order arrives.
The move A request pulls the location history they hold and where it went.
“may constitute a 'sale' or 'sharing' of your Personal Information”
In the US, order-linked identifiers flow to advertising partners as something of value, and the wording keeps it a maybe. The flow runs on by default and switching it off is left to you.
The move A request demands opt-out of that sale and sharing and records it.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.